The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Installation requirements

Prev Next

Trellix CP has specific system, certificate, and network requirements for installation and operation.

For details about ePolicy Orchestrator - On-prem requirements, see the ePolicy Orchestrator - On-prem documentation.

Requirement

Details

Software

  • ePolicy Orchestrator - On-prem, versions 5.1 and later, on-premise only

  • Java SE 8.0 or later JRE

Hardware (physical or virtual)

  • 16 GB RAM

  • Dual Core CPU

Operating system

  • Windows Server 2008 64-bit with Service Pack 2 or later

  • Windows Server 2008 R2 64-bit with Service Pack 1 or later

  • Windows Server 2012 64-bit

  • Windows Server 2012 R2 64-bit

Note

For the latest information on supported platforms, environments, and operating systems, see KB86369.

Active Directory

You must know the:

  • Domain controller name or IP address of the LDAP server

  • Port number that LDAP runs on

SSL certificate

  • Public (not self-signed)

  • Obtained from a recognized authority like Verisign or Go Daddy

  • Matches the address (A) record defined in the Domain Name System (DNS) unless a wildcard (*) certificate is used

    Note

    In high availability environments, you can associate a wildcard certificate with multiple Trellix CP servers.

Certificate KeyStore

You must have a Certificate KeyStore (in Java KeyStore format) containing the public SSL certificate. Detailed instructions for importing a public certificate to the KeyStore can be found in the Tomcat documentation.

https://tomcat.apache.org/tomcat-7.0-doc/ssl-howto.html

You must know the:

  • KeyStore password

  • KeyStore alias given to the SSL certificate

Network

  • You must have a valid, externally facing URL to access the Trellix CP server

  • TCP port 443 must be free and available on the server

Router and firewall access rules

You must configure Windows Firewall on the Trellix CP server to:

  • Allow incoming traffic from all sources on TCP port 443

  • Allow incoming and outgoing traffic to LDAP port

Installation account

  • Use a valid LDAP account for installation.

    Note

    We recommend using service account credentials.

  • Use the same LDAP account to install the Trellix CP server and extension.

  • Elevated permissions aren't required.